# What's the best way to secure Dgraph Cloud (via GCP with HA (and replication) setup) from DDoS attacks?

**URL:** <https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115>\
**Category:** Dgraph Cloud\
**Tags:** kind:question\
**Created:** [November 22, 2021, 10:06am UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115 "2021-11-22T10:06:10Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Juri](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/juri/32/8872_2.png) [@Juri](https://discuss.dgraph.io/u/Juri)\
**Post date:** [November 22, 2021, 10:06am UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115/1 "2021-11-22T10:06:10Z")

</div>

Hi,  
If I use Dgraph Cloud on Google Cloud with High Availability (and replication) setup;

how can I secure my Dgraph Cloud (Endpoints) from DDoS attacks?

I know that it’s done by Google Load Balancer + Google Cloud Armor;

but that’s how it’s done if you run your own Kubernetes.

But Dgraph Cloud is a managed service, GKE are managed by the Dgraph Team. So I don’t really want to mess up with any settings.

So, how should I handle/solve this problem/use-case?

Or is there already a service by Dgraph Cloud to enable anti-ddos?

---

<div class="post-metadata">

**Author:** ![MichelDiz](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/micheldiz/32/11873_2.png) [@MichelDiz](https://discuss.dgraph.io/u/MichelDiz)\
**Post date:** [November 22, 2021, 5:19pm UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115/2 "2021-11-22T17:19:57Z")

</div>

Dgraph has no solution for this, you should use things like CloudFlare and such.

PS. I think Dgraph uses CloudFlare. Need to check, but we use it everywhere.

---

<div class="post-metadata">

**Author:** ![Juri](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/juri/32/8872_2.png) [@Juri](https://discuss.dgraph.io/u/Juri)\
**Post date:** [November 22, 2021, 6:03pm UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115/3 "2021-11-22T18:03:37Z")

</div>

Can I secure my GraphQL endpoint with Cloudflare? how? Sure with CNAME or something like that, but the original endpoint would be still accesable. This requires once again a setup like VPC, and this has to be done on Google Cloud. And i dunno if I even have access to that if I use dgraph cloud, else I still don’t wanna mess up with that (changing dgraph cloud network settings and so on)

I would really appreciate a Tutorial to safely do that

> **[GitHub - cloudflare/cloudflared: Cloudflare Tunnel client (formerly Argo Tunnel)](https://github.com/cloudflare/cloudflared)**
>
> Cloudflare Tunnel client (formerly Argo Tunnel). Contribute to cloudflare/cloudflared development by creating an account on GitHub.

> **[Use cloudflared to expose a Kubernetes app to the Internet · Cloudflare Zero...](https://developers.cloudflare.com/cloudflare-one/tutorials/many-cfd-one-tunnel)**
>
> You can use Cloudflare Tunnel to connect applications and servers to Cloudflare’s network. Tunnel relies on a piece of software, cloudflared , to …

---

<div class="post-metadata">

**Author:** ![Juri](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/juri/32/8872_2.png) [@Juri](https://discuss.dgraph.io/u/Juri)\
**Post date:** [November 23, 2021, 11:47am UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115/4 "2021-11-23T11:47:44Z")

</div>

Would be really cool if you guys would establish a partnership for that product (DDoS protection) as well @dmai So that we can activate Cloudflare DDoS protection in Dgraph Cloud out of the box. Being able to build applications with peace of mind without having to fear exposing the GraphQL/DQL endpoints to the internet

but it also doesn’t has to be cloudflare, GCP Armor is OK too

> **[Kubernetes Security & Performance](https://www.cloudflare.com/integrations/kubernetes/)**
>
> The Cloudflare and Kubernetes integration makes multi-cloud, federated Kubernetes easy. Leverage the benefits of Cloudflare CDN, DNS, and DDoS protection services.

> **[Cloudflare + Google Cloud Platform | Cloud Services](https://www.cloudflare.com/integrations/google-cloud/)**
>
> The flexibility of Google Cloud Platform cloud services coupled with the power and protection of Cloudflare is just a button-click away.

> **[Cloudflare + GCP](https://www.cloudflare.com/multi-cloud/gcp/)**
>
> test2

 ![image](https://canada1.discourse-cdn.com/flex007/uploads/dgraph/original/2X/5/5b12661a664788cf8079abb13f31b85833c56f59.png)

---

<div class="post-metadata">

**Author:** ![Juri](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/juri/32/8872_2.png) [@Juri](https://discuss.dgraph.io/u/Juri)\
**Post date:** [November 25, 2021, 9:29pm UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115/5 "2021-11-25T21:29:15Z")

</div>

> [@MichelDiz](#):
>
> PS. I think Dgraph uses CloudFlare. Need to check, but we use it everywhere.

Holy Moly I just read that, sorry!! Maybe I overread that, I just read that now

Did you check that? Is dgraph cloud already using cloudflare protection? So that means my Dgraph Cloud GraphQL/DQL endpoints are protected?

this would be awesome! if yes, then maybe adding that as information on the website/docs would be good since that’s a very nice feature and one more reason to use dgraph

---

<div class="post-metadata">

**Author:** ![MichelDiz](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/micheldiz/32/11873_2.png) [@MichelDiz](https://discuss.dgraph.io/u/MichelDiz)\
**Post date:** [November 26, 2021, 3:03am UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115/6 "2021-11-26T03:03:16Z")

</div>

I’m pretty sure that we use in the websites, like the UI, docs, main site and such. But not sure about the servers.

Pinging @dmai

- Can you tell if we use some level of DDOS protection from CloudFlare in Dgraph Cloud?

---

<div class="post-metadata">

**Author:** ![dmai](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/dmai/32/1254_2.png) [@dmai](https://discuss.dgraph.io/u/dmai)\
**Post date:** [November 26, 2021, 8:56pm UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115/7 "2021-11-26T20:56:27Z")

</div>

There’s no specific DDoS protection set up today for Dgraph Cloud. The major cloud providers (AWS, GCP, and Azure at least) already provide built-in basic DDoS protection for up to layer 4 traffic.

We’ll be enabling layer 7 DDoS protection with a WAF soon, but I wouldn’t expect anything specifically from CloudFlare at this time.

---

<div class="post-metadata">

**Author:** ![thelovesmith](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/thelovesmith/32/9939_2.png) [@thelovesmith](https://discuss.dgraph.io/u/thelovesmith)\
**Post date:** [January 2, 2023, 7:30pm UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115/8 "2023-01-02T19:30:13Z")

</div>

> Did you check that? Is dgraph cloud already using cloudflare protection? So that means my Dgraph Cloud GraphQL/DQL endpoints are protected?

Just seeing this thread, guys. Is there any update on this?

> We’ll be enabling layer 7 DDoS protection with a WAF soon, but I wouldn’t expect anything specifically from CloudFlare at this time.

Also, did you guys ever enable layer 7 DDOS with WAF? I want to know what things I need to take care of security-wise before our app goes live.

@dmai @MichelDiz Hey guys, Any updates on the protection mentioned above?

---

<div class="post-metadata">

**Author:** ![MichelDiz](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/micheldiz/32/11873_2.png) [@MichelDiz](https://discuss.dgraph.io/u/MichelDiz)\
**Post date:** [January 10, 2023, 11:19pm UTC](https://discuss.dgraph.io/t/whats-the-best-way-to-secure-dgraph-cloud-via-gcp-with-ha-and-replication-setup-from-ddos-attacks/16115/9 "2023-01-10T23:19:08Z")

</div>

No, but we can check about this this year

cc @Raphael
